SASE

SASE five components split into networking and security explained

SASE is an architecture born from a problem most startups never had: traffic hauled back to a head office to be inspected. Knowing which parts of it apply to you saves a large amount of money.

  • Glossary
  • Network

The short answer

SASE, pronounced sassy, stands for secure access service edge. It converges networking and network security into one cloud-delivered service, so that inspection and access decisions happen close to the user rather than inside a corporate data centre. The five components are SD-WAN, secure web gateway, cloud access security broker, zero trust network access and firewall as a service.

It is an enterprise architecture. Whether you need all of it, some of it or one piece of it depends almost entirely on whether you own offices and private networks.

The five SASE components

NETWORKING SECURITY, ALSO SOLD ALONE AS SSE SD-WAN Routing traffic between sites intelligently SWG Web filtering CASB SaaS control ZTNA Private access FWaaS Cloud firewall All delivered from a cloud edge, close to the user, with identity as the policy anchor For a cloud-native company, ZTNA is usually the only piece that earns its cost on day one.
ComponentWhat it does
SD-WANSoftware-defined routing between offices, data centres and cloud, replacing fixed private circuits
Secure web gatewayInspects outbound web traffic, filters categories and blocks malicious destinations
Cloud access security brokerVisibility and policy over SaaS use, including sanctioned and unsanctioned applications
ZTNAAccess to private applications gated per user and per device, with no network-level trust
Firewall as a serviceFirewall capability delivered from the cloud rather than from appliances you rack

SASE and SSE

SSE, security service edge, is the same architecture with the networking removed. It is the security half: secure web gateway, cloud access security broker and ZTNA, without SD-WAN.

The reason the term exists is that many buyers wanted the security convergence but had no appetite to replace their networking at the same time. For a company with no branch offices and no private circuits, SSE is usually the relevant conversation and SASE is the term the vendor happened to lead with.

What SASE actually solves

The original problem was backhaul. A company with offices and a data centre routed all traffic back to headquarters so it could pass through the security appliances installed there. That worked when applications lived in the data centre. Once applications moved to SaaS and cloud, sending a user’s traffic across the country and back to reach a service hosted near them became slow, expensive and pointless.

If you never had a data centre, you never had the backhaul problem

A cloud-native company with a distributed team and everything in SaaS did not inherit the architecture SASE was designed to replace. That does not make the security functions irrelevant, but it does mean buying a full suite to solve a problem you never had is an expensive way to acquire one control you do need. The pieces are separable, and vendors prefer that you not notice.

What a lean team needs from it

ComponentWorth it for a 10 to 50 person company?
ZTNAYes. Private servers and internal tools need access gated by user and device, and this is the piece that replaces a VPN
Web filteringOften, though usually adequate as an endpoint control rather than a network service
SaaS visibilitySometimes. Valuable once SaaS sprawl is real, less so at twenty applications
Cloud firewallRarely as a separate purchase. Cloud provider controls and a WAF usually cover it
SD-WANAlmost never. It solves routing between sites you do not have

The through line is that identity, not network location, is what the architecture actually anchors on. Get access management, MFA and device posture right and you have the substance of the model, whatever the suite is called.

Where Osto fits

Osto is not a SASE suite and does not claim to be. There is no SD-WAN and no managed network fabric. What Osto delivers is the piece a cloud-native company actually needs from the architecture, plus the controls around it.

ZTNA provisions a private domain for your cloud servers and resources, unreachable unless the endpoint agent is installed and MFA is enforced. Alongside it sit endpoint protection, device and content controls, data loss prevention, web and API protection and inbound email security. The access decisions, endpoint state and application traffic all correlate in the same SIEM, which is the part a stitched-together edge stack struggles to deliver. If you have branch offices and private circuits, a full suite is a reasonable conversation. If you do not, this is the shorter path to the same outcome.

Platform walkthrough

The piece you actually need

Private access gated by user and device, with endpoint, data and application controls correlating in the same stack. No network fabric to replace. One owner, one dashboard.

Book a demo

ZTNA without the suite · Built for lean teams · One platform, everything

Frequently asked questions

What is SASE?

Secure access service edge, an architecture that converges networking and network security into one cloud-delivered service. Its components are SD-WAN, secure web gateway, cloud access security broker, ZTNA and firewall as a service, with identity as the policy anchor.

What is the difference between SASE and SSE?

SSE, security service edge, is the security half without the networking. It covers web gateway, SaaS control and ZTNA but not SD-WAN. Companies without branch offices or private circuits usually want SSE rather than the full architecture.

Does a startup need SASE?

Usually not as a suite. The architecture was designed to replace backhauling traffic to a corporate data centre, which cloud-native companies never did. ZTNA is normally the one component that earns its cost immediately.

Is SASE the same as zero trust?

No. Zero trust is a principle: verify every request rather than trusting a network location. SASE is one architecture for delivering it, and ZTNA is the component within it that applies the principle to private application access.

Does SASE replace a VPN?

The ZTNA component does. A VPN places a user on the network and trusts them broadly. ZTNA grants access to specific resources per user and per device, with no network-level trust, which is a materially different security posture.